Vulnerabilities exploitable today
374,209in current view
Single score combining CVSS, KEV membership and EPSS. Every CVE with its own record — timeline from publication to active exploitation.
In KEV catalog1,710
New KEV · 24H0
Exploit Today ≥ 701,646
Distribution · last window
- Critical2,204
- High7,819
- Medium6,373
- Low706
Window
Severity
Flags
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-30677—28.2%
——8——CVE-2003-0420—28.2%
——8——CVE-2004-2611—28.2%
——8——CVE-2024-58257—28.2%
——8——CVE-2023-1515—28.2%
——8——CVE-2023-44101—28.2%
——8——CVE-2002-1711—28.2%
——8——CVE-2024-28968—28.2%
——8——CVE-2026-841878.2 HIG28.2%
——8AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed by sending crafted POST requests with schedule identifiers. Attackers can exploit the unguarded RTMP callback endpoint to modify scheduled broadcast status fields by supplying fabricated stream keys matching the pattern -ps-<N>, silently canceling any scheduled live broadcast without credentials or authorization.8dCVE-2025-2413—28.2%
——8——CVE-2024-35545—28.2%
——8——CVE-2025-2412—28.2%
——8——CVE-2024-37031—28.2%
——8——CVE-2025-43504—28.2%
——8——CVE-2025-15236—28.2%
——8——CVE-2026-563286.5 MED28.2%
——8Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously, while unnamed /updates requests without defaultChannel implicitly resolve to a single hidden winner channel. An authorized app or channel manager can create ambiguous default update state and silently influence which bundle unnamed clients receive, breaking release routing integrity and predictability.77dCVE-2026-1839—28.2%
——8——CVE-2010-3431—28.2%
——8——CVE-2023-3288—28.2%
——8——CVE-2013-5522—28.2%
——8——CVE-2025-138037.3 HIG28.2%
——8A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /mediacrush/paths.py of the component Header Handler. Such manipulation of the argument Host leads to improper neutralization of http headers for scripting syntax. The attack can be launched remotely.14dCVE-2026-344515.4 MED28.2%
——8Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.81.0, the local filesystem memory tool in the Anthropic TypeScript SDK validated model-supplied paths using a string prefix check that did not append a trailing path separator. A model steered by prompt injection could supply a crafted path that resolved to a sibling directory sharing the memory root's name as a prefix, allowing reads and writes outside the sandboxed memory directory. This issue has been patched in version 0.81.0.54dCVE-2026-350258.1 HIG28.2%
——8ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with /proc/self/root in the RNFR command handler. Attackers can exploit the unresolved symlink components in dir_canonical_path() to cause dir_check() to perform lexical path comparisons that match no configured Directory block, enabling rename operations on files in DenyAll-protected directories and subsequent retrieval of those files. Mitigation: Sessions configured with DefaultRoot (chroot) are not affected, as chroot changes the directory to which /proc/self/root resolves.64dCVE-2021-43204—28.2%
——8——CVE-2013-5415—28.2%
——8——CVE-2019-3621—28.2%
——8——CVE-2026-6552—28.2%
——8Rejected reason: This CVE ID has been rejected. GitLab determined that the reported behavior does not constitute a vulnerability: linking a group SAML identity requires the user to explicitly consent to that group controlling their GitLab account for sign-in, and management of group SAML identities by a group Owner is therefore expected behavior rather than an authorization bypass. No GitLab version was affected.47dCVE-2025-26696—28.2%
——8——CVE-2016-0432—28.2%
——8——CVE-2016-0406—28.2%
——8——CVE-2022-29204—28.2%
——8——CVE-2021-3581—28.2%
——8——CVE-2018-4395—28.2%
——8——CVE-2024-28966—28.2%
——8——CVE-2025-2415—28.2%
——8——CVE-2025-68133—28.2%
——8——CVE-2023-2870—28.2%
——8——CVE-2025-51954—28.2%
——8——CVE-2024-42906—28.2%
——8——CVE-2023-51665—28.2%
——8——